Create New User Whilst Logged On

Disclosed: 2017-01-13 00:28:37 By id-is-vulnerable To starbucks
None
Vulnerability Details
The website www.teavana.com allows users already logged on to create new account with a very simple url redirect. When an account is created a page is displayed with your account information and what you want to update. By simply refreshing the page allows you to create a new account whilst still logged on. If you try to recreate the same account with the same email but different password, there will be no error message displayed though when you try to login, the password will be incorrect.
Actions
View on HackerOne
Report Stats
  • Report ID: 193478
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 4
Share this report